|
#1
|
|||
|
|||
|
STOP: c000021a Winlogon.exe Blue Screen of Death error
I've been having this problem for the last few days. I've tried going back to a previous time in system restore to a few days before I started having this problem. Before I did System restore I kept on getting the BSOD a few seconds after Windows had restarted. After System Restore, it probably takes about 5-15 minutes before I get the screen. So unlike others with the same problem I can actually access my Windows regularly and through Safe Mode for a few minutes before I get the BSOD screen again.
======================= I get the following Blue Screen of Death error: STOP: c000021a {Fatal System Error} The Windows Logon Process system process terminated unexpectedly with a status of 0xc0000005 (0xc0000000 0xc0000000). The system has been shut down. ======================= My HijackThis logfile while in Safe Mode Logfile of HijackThis v1.99.1 Scan saved at 11:29:22 PM, on 23/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\fkothdbu.dll",forkonce O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\TEMP\IXP005.TMP\" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by129w.bay129.mail.live.com/m...s/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/micr...?1181077104234 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1181077032984 O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\lgbadfwm.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing) O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe O23 - Service: SiS WirelessLan Service (SiSWLSvc) - Unknown owner - C:\Program Files\TRENDnet\TEW-424UB\SiSWLSvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Last edited by Sakura_Fanelia; August 24th, 2007 at 04:54 AM. Reason: more info |
|
#2
|
||||
|
||||
|
Howdy:
You wouldn't happen to have Roxio GoBack installed now would you? Murray |
|
#3
|
|||
|
|||
|
=======================
Last entry from my Dr.Watson Debugger log file from today: Application exception occurred: App: \??\C:\WINDOWS\system32\winlogon.exe (pid=776) When: 23/08/2007 @ 23:36:45.046 Exception number: c0000005 (access violation) *----> System Information <----* Computer Name: MAHA-DESKTOP User Name: SYSTEM Terminal Session Id: 0 Number of Processors: 2 Processor Type: x86 Family 15 Model 3 Stepping 3 Windows Version: 5.1 Current Build: 2600 Service Pack: 2 Current Type: Multiprocessor Free Registered Organization: Registered Owner: Maha Salim Basheikh *----> Task List <----* 0 System Process 4 System 700 smss.exe 752 csrss.exe 776 winlogon.exe 820 services.exe 840 lsass.exe 1004 svchost.exe 1052 svchost.exe 1092 svchost.exe 1112 InCDsrv.exe 1296 svchost.exe 1328 svchost.exe 1340 Error 0xD0000022 1736 Explorer.EXE 2036 Error 0xD0000022 400 Error 0xD0000022 408 spoolsv.exe 556 Error 0xD0000022 672 mdm.exe 1644 SiSWLSvc.exe 1208 Logon.tmp 1220 ups.exe 1716 nmsrvc.exe 2352 wuauclt.exe 3148 alg.exe 3612 nmapp.exe 2096 WgaTray.exe 2120 Error 0xD0000022 2376 is67533.exe 3688 ctfmon.exe 3960 WeatherEye.exe 2164 DvzIncMsgr.exe 4092 mantispm.exe 3608 drwtsn32.exe *----> Module List <----* (0000000001000000 - 0000000001080000: \??\C:\WINDOWS\system32\winlogon.exe (00000000011b0000 - 00000000011e2000: C:\WINDOWS\system32\WgaLogon.dll (0000000001620000 - 0000000001635000: C:\WINDOWS\system32\awtropo.dll (00000000016c0000 - 00000000016d5000: C:\WINDOWS\system32\ddcdbxu.dll (0000000001700000 - 0000000001715000: C:\WINDOWS\system32\awturrr.dll (0000000001760000 - 0000000001775000: C:\WINDOWS\system32\khfdeed.dll (0000000001780000 - 0000000001795000: C:\WINDOWS\system32\pmnnlkj.dll (00000000017a0000 - 00000000017b5000: C:\WINDOWS\system32\jkkligh.dll (0000000001800000 - 0000000001815000: C:\WINDOWS\system32\yaywvtt.dll (0000000001880000 - 0000000001b45000: C:\WINDOWS\system32\xpsp2res.dll (000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll (0000000010000000 - 00000000100c0000: C:\WINDOWS\system32\vtsqr.dll (0000000020000000 - 0000000020017000: C:\WINDOWS\system32\odbcint.dll (000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll (000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\NETAPI32.dll (000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\COMCTL32.dll (00000000629c0000 - 00000000629c9000: C:\WINDOWS\system32\LPK.DLL (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll (0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll (0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll (0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll (00000000723d0000 - 00000000723ec000: C:\WINDOWS\system32\WINSCARD.DLL (0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv (0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv (0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV (0000000074320000 - 000000007435d000: C:\WINDOWS\system32\ODBC32.dll (0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll (00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime (0000000075930000 - 000000007593a000: C:\WINDOWS\system32\PROFMAP.dll (0000000075940000 - 0000000075948000: C:\WINDOWS\system32\NDdeApi.dll (0000000075950000 - 000000007596a000: C:\WINDOWS\system32\WlNotify.dll (0000000075970000 - 0000000075a67000: C:\WINDOWS\system32\MSGINA.dll (0000000075e90000 - 0000000075f40000: C:\WINDOWS\system32\sxs.dll (0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll (0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL (00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll (0000000076600000 - 000000007661d000: C:\WINDOWS\system32\cscdll.dll (0000000076780000 - 0000000076789000: C:\WINDOWS\system32\SHFOLDER.dll (00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll (0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll (0000000076bb0000 - 0000000076bb5000: C:\WINDOWS\system32\sfc.dll (0000000076bc0000 - 0000000076bcf000: C:\WINDOWS\system32\REGAPI.dll (0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL (0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll (0000000076c60000 - 0000000076c8a000: C:\WINDOWS\system32\sfc_os.dll (0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll (0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll (0000000076f50000 - 0000000076f58000: C:\WINDOWS\system32\WTSAPI32.dll (0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll (0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL (0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll (0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll (00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll (0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL (00000000776c0000 - 00000000776d1000: C:\WINDOWS\system32\AUTHZ.dll (00000000776e0000 - 0000000077703000: C:\WINDOWS\system32\SHSVCS.dll (0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll (0000000077a20000 - 0000000077a74000: C:\WINDOWS\system32\cscui.dll (0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll (0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll (0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll (0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll (0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll (0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll (0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll (0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll (0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll (0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll (0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll (0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll (0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll (000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll (000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll (000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll (000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll *----> State Dump for Thread Id 0xdcc <----* eax=00000000 ebx=01390000 ecx=022bffb0 edx=7c90eb94 esi=00000000 edi=00000000 eip=7c883f9c esp=022bffb8 ebp=022bffec iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - function: kernel32 7c883f74 0000 add [eax],al 7c883f76 0000 add [eax],al 7c883f78 0000 add [eax],al 7c883f7a 0000 add [eax],al 7c883f7c 0000 add [eax],al 7c883f7e 0000 add [eax],al 7c883f80 0000 add [eax],al 7c883f82 0000 add [eax],al 7c883f84 0000 add [eax],al 7c883f86 0000 add [eax],al 7c883f88 0000 add [eax],al 7c883f8a 0000 add [eax],al 7c883f8c 0000 add [eax],al 7c883f8e 0000 add [eax],al 7c883f90 0000 add [eax],al 7c883f92 0000 add [eax],al 7c883f94 0000 add [eax],al 7c883f96 0000 add [eax],al 7c883f98 0000 add [eax],al 7c883f9a 0000 add [eax],al FAULT ->7c883f9c 0000 add [eax],al ds:0023:00000000=?? 7c883f9e 0000 add [eax],al 7c883fa0 0000 add [eax],al 7c883fa2 0000 add [eax],al 7c883fa4 0000 add [eax],al 7c883fa6 0000 add [eax],al 7c883fa8 0000 add [eax],al 7c883faa 0000 add [eax],al 7c883fac 0000 add [eax],al 7c883fae 0000 add [eax],al 7c883fb0 0000 add [eax],al 7c883fb2 0000 add [eax],al 7c883fb4 0000 add [eax],al 7c883fb6 0000 add [eax],al 7c883fb8 0000 add [eax],al 7c883fba 0000 add [eax],al 7c883fbc 0000 add [eax],al 7c883fbe 0000 add [eax],al 7c883fc0 0000 add [eax],al 7c883fc2 0000 add [eax],al 7c883fc4 0000 add [eax],al *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 022bffec 00000000 7c883f9c 01390000 00000000 kernel32+0x83f9c *----> Raw Stack Dump <----* 00000000022bffb8 83 b6 80 7c 00 00 39 01 - 00 00 00 00 00 00 00 00 ...|..9......... 00000000022bffc8 00 00 39 01 00 50 fd 7f - 05 00 00 c0 c0 ff 2b 02 ..9..P........+. 00000000022bffd8 dc fb 2b 02 ff ff ff ff - a8 9a 83 7c 90 b6 80 7c ..+........|...| 00000000022bffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 9c 3f 88 7c .............?.| 00000000022bfff8 00 00 39 01 00 00 00 00 - 00 00 00 00 00 00 00 00 ..9............. 00000000022c0008 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0018 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0028 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0038 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0048 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0058 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0068 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0078 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0088 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c0098 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c00a8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c00b8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c00c8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c00d8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000022c00e8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ That's all the info I could gather. Please help. My computer is essentially useless right now. |
|
#4
|
||||
|
||||
|
That's nice. Now, how about answering my inquiry?
Murray |
|
#5
|
|||
|
|||
|
Oh, sorry. I didn't see that post. Didn't even know anyone had posted.
But, no. I don't have Roxio. Never heard of it. |
|
#6
|
||||
|
||||
|
Okay.. Have you tried the "Last Known Good Configuration" bootup option?
Murray |
|
#7
|
|||
|
|||
|
Yes, there's no change.
|
|
#8
|
||||
|
||||
|
Alright.. so, it won't boot normally at all right but you can get into Safe Mode. Right so far?
What did you install (hardware, software, codecs, etc) or uninstall just before the problem appeared? Also, do you have your XP cd handy? Murray |
|
#9
|
|||
|
|||
|
Actually it boots normally. It's just that after a few minutes I get that BSOD.
I installed something a few days ago yes ( I forget what at the moment, but it was some program -_-) but I not only uninstalled, I also used System Restore to go back to a day when I had no problems. |
|
#10
|
||||
|
||||
|
Quote:
![]() What was the program and where did you get it from? Murray |
|
#11
|
|||
|
|||
|
I think it was Fable: The Lost Chapters ( a game )
|
|
#12
|
||||
|
||||
|
Great. Now, did you happen to use Ares to get it? And what about your XP cd - do you have it handy?
Murray |
|
#13
|
|||
|
|||
|
No, I think my little brother downloaded it through a torrent and then burnt it to a DVD-R. He wouldn't use Ares. And yes, I have my XP CD handy.
|
|
#14
|
||||
|
||||
|
Quote:
Boot using your XP cd and run the "Repair" option. You will have to re-install all Service Packs and Critical Updates again after. Murray |
|
#15
|
|||
|
|||
|
Well, it worked on his computer fine with no problems... Might that make a difference? The only reason I uninstalled it was because my computer didn't even meet the minimum video card requirements.
|
![]() |
| Bookmarks |
«
Previous Topic
|
Next Topic
»
| Topic Tools | |
|
|
All times are GMT +1. The time now is 05:07 AM.









